W
Security Free WordPress.org

WPScan – WordPress Security Scanner

3.8 (28 reviews)
· 8K+ active installs · By ethicalhack3r
Active Installs
8K+
Rating
3.8 / 5
Version
v1.16
Last Updated
Jan 2026
Share

Plugin Review

AI-Researched

What is WPScan?

WPScan is a WordPress security scanner that checks your site against a manually curated database of over 21,000 known vulnerabilities. Developed by security researcher ethicalhack3r, the plugin has been available for 7 years. It scans your WordPress core, plugins, and themes against this database. The plugin currently shows 8K+ active installs. It holds a 3.8/5 rating from 28 reviews, with 64% of those being 4% being one-star.

This tool is unique because it relies on the WPScan WordPress Vulnerability Database, which has been updated daily since 2014. The plugin acts as a dedicated wordpress vulnerability scanner for site owners. It also performs additional security checks that do not require an API token, such as looking for debug.log files and checking if XML-RPC is enabled. However, the plugin description itself notes it is no longer actively supported for non-enterprise customers, directing users toward Jetpack Protect instead.

Key Features of WPScan

  • Vulnerability Database Scanning – Checks your WordPress version, plugins, and themes against a database of more than 21,000 known security vulnerabilities.
  • Automated Daily Scans – Schedule a wordpress security scan to run automatically each day, with configurable notification settings.
  • Email Notifications – Receive email alerts when new vulnerabilities are found on your site.
  • Admin Toolbar Indicator – Shows an icon in the WordPress admin bar displaying the total number of security vulnerabilities detected.
  • Additional Security Checks – Scans for debug.log files, wp-config.php backups, exported database files, weak passwords, and HTTPS status without using an API call.
  • Free API Plan – Offers 25 API requests per day for free, which covers roughly 50% of WordPress websites based on average plugin counts.
  • wp-config.php Configuration – Allows you to set the API token or disable scanning entirely using PHP constants in your wp-config.php file.
  • Code Repository Detection – Checks for exposed code repository files that could leak sensitive information.

Who Should Use WPScan?

WPScan is best suited for site owners who want a straightforward best wordpress security scanner plugin with a known vulnerability database. The free tier supports 25 API calls daily, which covers about half of all WordPress sites. If your site has 22 plugins on average, you will use roughly 24 API calls per scan. This makes the free plan usable for small to medium sites. Users comfortable editing wp-config.php files will find the advanced configuration options useful.

This plugin is not ideal for beginners who need active support or regular updates. The developer has shifted focus to enterprise customers. The 25% one-star rating suggests many users encountered issues with scanning or support. If you want to scan wordpress for vulnerabilities without paying, the free API token works. However, the plugin's own documentation recommends switching to Jetpack Protect for ongoing free protection.

Installation & Setup

Installation is standard: upload the plugin folder to /wp-content/plugins/ and activate it through the WordPress admin. You must register for a free API token on the WPScan website. Then save that token on the settings page or define it in wp-config.php using define( 'WPSCAN_API_TOKEN', '$your_api_token' );. The process is beginner-friendly if you can follow a registration link, but the wp-config.php method requires basic file editing skills.

Support & Community

Support data for the last 2 months shows 0 open threads and 0 resolved threads, resulting in a 0% resolution rate. This aligns with the plugin description stating it is no longer actively supported for non-enterprise customers. The rating distribution is polarized: 64% five-star reviews praise the vulnerability database and scanning accuracy, while 25% one-star reviews likely reflect the lack of support and potential scanning issues. With 8K+ installs and version 1.16 last updated on Jan 12, 2026, the plugin remains functional but is effectively in maintenance mode for free users. The community relies on the WPScan Twitter account and the public vulnerability database for ongoing information.

Pros & Cons

What's Good
  • Leverages a manually curated database of over 21,000 known vulnerabilities, updated daily by security specialists.
  • Free API plan covers roughly 50% of WordPress sites (up to 25 requests/day) and includes checks for debug.log, XML-RPC, and weak passwords without requiring a token.
  • Scans for vulnerabilities in WordPress core, plugins, and themes, with options for automated daily scans and email notifications.
  • 64% of its 28 ratings are 5-star, indicating a generally positive reception among users who find it functional.
  • Active installs exceed 8K+, showing a modest but established user base for a niche security tool.
Drawbacks
  • Plugin is no longer actively supported for non-enterprise customers, with zero resolved support threads out of zero total threads.
  • 25% of its 28 ratings are 1-star, reflecting notable user dissatisfaction, likely due to the deprecation and limited free API requests.
  • Free plan allows only 25 API requests per day, which may not cover sites with more than 22 plugins or themes, forcing users to upgrade or seek alternatives.
  • Requires registration for an API token even for basic functionality, adding an extra step before scanning can begin.

Technical Details

Requires WordPress
3.4+
Requires PHP
5.5+
Tested up to WP
6.9.5
First Released
2019 (7+ years)
Support (last 2 months)
0 threads

Feature Tags

hack security vulnerability wpscan wpvulndb

Frequently Asked Questions